CVE-2026-6307Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 31 mentions across 18 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 17 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 24 signals
  • Disclosure: 14 classified signals
  • General: 4 classified signals
  • Peaked 7d ago at 4 mentions (2026-07-01); latest day: 1
  • 31 total mentions across 18 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline31 mentions / 18d
01234Mentions · 2026-04-15: 2Mentions · 2026-04-16: 3Mentions · 2026-04-29: 1Mentions · 2026-05-03: 1Mentions · 2026-05-05: 1Mentions · 2026-05-07: 1Mentions · 2026-05-14: 1Mentions · 2026-05-22: 1Mentions · 2026-06-29: 3Mentions · 2026-06-30: 2Mentions · 2026-07-01: 4Mentions · 2026-07-02: 3Mentions · 2026-07-20: 2Mentions · 2026-07-21: 2Mentions · 2026-07-29: 1Mentions · 2026-08-13: 1Mentions · 2026-08-16: 1Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-06-29: 3PoC Mentioned / Linked · 2026-06-30: 1PoC Mentioned / Linked · 2026-07-01: 3PoC Mentioned / Linked · 2026-07-02: 2PoC Mentioned / Linked · 2026-07-21: 2PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-08-20: 1Exploit Tool / Code · 2026-07-01: 3Exploit Tool / Code · 2026-07-02: 1Exploit Tool / Code · 2026-07-20: 1Exploit Tool / Code · 2026-07-21: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-07-01: 3Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 3Technical Details · 2026-04-29: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-29: 3Technical Details · 2026-06-30: 2Technical Details · 2026-07-01: 4Technical Details · 2026-07-02: 2Technical Details · 2026-07-20: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-16: 104-1504-1604-2905-0305-0505-0705-1405-2206-2906-3007-0107-0207-2007-2107-2908-1308-1608-20
Signal classification5 categories
Disclosure
1445.2%
PoC
1135.5%
General
412.9%
Patch
13.2%
Exploit
13.2%
Referenced assets22 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure1Patch1
2026-04-163
Disclosure3
2026-04-291
Disclosure1
2026-05-031
General1
2026-05-051
PoC1
2026-05-071
Disclosure1
2026-05-141
PoC1
2026-05-221
Disclosure1
2026-06-293
Disclosure1PoC2
2026-06-302
Disclosure2
2026-07-014
Disclosure1PoC3
2026-07-023
Disclosure1PoC2
2026-07-202
Exploit1General1
2026-07-212
PoC2
2026-07-291
General1
2026-08-131
Disclosure1
2026-08-161
Disclosure1
2026-08-201
General1
Full discourse20 posts
  • Nebula Security@nebusecurity
    PoC

    Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs Today we bring the Spear of Longinus 1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape Our CVE-2026-6307 writeup http://nebusec.ai/research/v8-cve-2026-6307-writeup/?p https://t.co/EwYhAT7lPI

    Post summary

    The tweet announces a single-bug exploit for CVE‑2026‑6307 with a linked writeup that likely contains a PoC, but it does not report active exploitation or patch information.

    8108353631351.0K
    7.1K followersView on X
  • 0xSha@0xsha
    PoC

    Dropping a RCE PoC for CVE-2026-6307, a Google Chrome V8 type-confusion bug patched in Chrome 147.0.7727.101. Link in first reply. 👹 https://t.co/rRwH4z8Mh1

    Post summary

    A Proof of Concept RCE PoC has been released for CVE-2026-6307, a type‑confusion vulnerability in Chrome's V8 engine, with a link to the code and noting the patch version.

    429028315827.6K
    10.8K followersView on X
  • Javi T.@javi_teje
    PoC

    We said it was raining Chrome bugs. Part 2 brings the thunder. @5tratan continues the CVE-2026-6307 analysis, taking the TurboFan JS-to-Wasm deopt type confusion from root cause to PoC. https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion-part-2/

    Post summary

    The post presents a proof of concept for CVE‑2026‑6307, detailing a TurboFan JS-to‑Wasm deopt type confusion, but does not indicate a patch or evidence of live exploitation.

    0250114937.1K
    99 followersView on X
  • Jλckλι@J4ck3LSyN
    PoC

    CVE-2026-6307 PoC + Report: [PoC]: https://github.com/J4ck3LSyN-Gen2/CVE-2026-6307-Longinus [Report]: https://github.com/J4ck3LSyN-Gen2/Reports/blob/main/OS-IS-CVE-2026-6307-07-2026.md [Writeup]: https://nebusec.ai/research/v8-cve-2026-6307-writeup/ Special thanks to @v8js & @nebusecurity for the patch and write-up and to @YogSoth0 for the heads up. #CyberSecurity #InfoSec #CVE #V8 #RCE https://t.co/XMnpoREKO8

    Post summary

    The post announces a PoC and detailed write-up for CVE‑2026‑6307, references a patch, and indicates the issue is an RCE, with no mention of active exploitation.

    522099516.7K
    437 followersView on X
  • Javi T.@javi_teje
    Disclosure

    It's been raining Chrome bugs lately, so we took a closer look. Part 1 by @5tratan is live: our analysis of CVE-2026-6307, a TurboFan JS-to-Wasm deopt type confusion bug. We cover the trigger and the background needed to follow along. https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion/

    Post summary

    The tweet announces a detailed analysis of a newly found Chrome vulnerability (CVE-2026-6307), outlining its type and trigger within the TurboFan JS-to-Wasm deoptimization flow.

    015087756.5K
    99 followersView on X
  • xia0o0o0o@Nyaaaaa_ovo
    PoC

    We spent a long time on this writeup. Hope you like it. One interesting thing is our human research team finishing the d8 shell exploit in <10min after Vega found this vulnerability. https://nebusec.ai/research/v8-cve-2026-6307-writeup/?p

    Post summary

    A writeup on CVE‑2026‑6307 presents a rapidly developed "d8 shell exploit," indicating a PoC exists, but lacks details on patches, active exploitation, or technical specifics.

    39089465.0K
    3.5K followersView on X
  • 0xSha@0xsha
    PoC

    PoC: https://github.com/0xsha/CVE-2026-6307 this is based on nebula writeup, so credit goes to @nebusecurity , This is renderer-only RCE and far from truly weaponized. Multiple frontier LLMs hammered on it for ~4 days to improve reliability, but there is still a lot left as open work (e.g Flag free, ASLR-on RCE)

    Post summary

    The post shares a PoC repository for CVE‑2026‑6307, identifies a renderer‑only RCE, and states it is not yet fully weaponized, with no evidence of active exploitation.

    411057434.4K
    10.8K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-6307 PT ID: PT-2026-33145 Vendor: Google Product: Chrome Description: Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Link: https://github.com/0xsha/CVE-2026-6307 #dbugs_vuln

    Post summary

    Proof of concept shows CVE-2026-6307 allows remote code execution via sandbox escape in Chrome; PoC code is hosted on GitHub, but no patch or active exploitation is reported.

    111068335.1K
    3.4K followersView on X
  • Blackstorm Security@blackstormsecbr
    Disclosure

    CVE-2026-6307 (Part 1): Turbofan JS-to-Wasm Deopt Type Confusion: https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion/ CVE-2026-6307 (Part 2): Turbofan JS-to-Wasm Deopt Type Confusion https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion-part-2/ #chrome #informationsecurity #vulnerability #turbofan #cybersecurity #exploitation https://t.co/H8T7GpkT97

    Post summary

    CVE‑2026‑6307, a Turbofan JS‑to‑Wasm deoptimization type‑confusion bug, is announced via two blog posts, but no PoC code, exploit details, or active exploitation reports are provided.

    013044273.6K
    2.1K followersView on X
  • YogSotho@YogSoth0
    Disclosure

    #CVE-2026-6307 V8 Exploit Kit #Longinus 2 Boundaries in One Bug - Piercing Chrome's Renderer and #V8 #Sandbox Overview | Attribute | Value | |-----------|-------| | **CVE** | CVE-2026-6307 | | **CVSS** | 9.8 (Critical) | | **Component** | Chrome/V8 TurboFan JIT Compiler | | **Bug Type** | Type Confusion via CSE/GVN FrameState Merging | | **Affected** | Chrome 106 - 146 (fixed in 147.0.7727.101) | | **Discovered By** | Vega (http://nebusec.ai) @nebusecurity #0days #cybersecurity #hacking #security #infosec #antisec #google #chrome

    Post summary

    Vega announced the critical CVE-2026-6307 type-confusion flaw in Chrome's V8 TurboFan JIT (v106‑146), with no mention of proofs or active attacks, but noting it is fixed in Chrome 147.0.7727.101.

    12143193.5K
    1.9K followersView on X
  • Blackstorm Security@blackstormsecbr
    Disclosure

    Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 https://nebusec.ai/research/v8-cve-2026-6307-writeup/ #cybercurity #informationsecurity #browser #exploitation #cve #exploit #vulnerability https://t.co/Nu8zhu3V0t

    Post summary

    A newly disclosed CVE-2026-6307 affecting Chrome’s renderer and V8 sandbox is announced with a research writeup available, but no PoC, exploit, patch, or active exploitation evidence is provided.

    03129221.9K
    2.4K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    PoC

    One bug Two sandboxes shattered. Chrome's V8 just got speared Longinus (CVE-2026-6307). that gives you renderer RCE without chaining anything else. Arbitrary read/write & full sandbox escape with a single vulnerability, No heap spray. 100% reliable, Hits 40+ Chrome versions going back years. https://x.com/nebusecurity/status/2071587218205086149/video/1

    Post summary

    The post announces a new Chrome V8 vulnerability (CVE-2026-6307) that permits renderer RCE and sandbox escape, presenting a Proof of Concept linked via a video.

    04025172.8K
    53.2K followersView on X
  • xvonfers@xvonfers
    General

    (CVE-2026-6307)[497404188][compiler] Type Confusion Exploited in v8ctf

    Post summary

    The passage identifies CVE-2026-6307 as a type‑confusion vulnerability that was leveraged in a v8ctf CTF exercise, but it offers no detailed PoC, exploit code, patch, or active‑wild exploitation evidence.

    1301773.1K
    5.0K followersView on X
  • Tashita Software Security@TashitaSoftSec
    Disclosure

    We're wrapping up the CVE-2026-6307 series with special effects. Or better said: WasmFX. Follow along as @5tratan attempts to escape the v8 sandbox. https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion-part-3

    Post summary

    The tweet announces the final part of the CVE-2026-6307 series, linking to a blog post that includes a proof‑of‑concept for a v8 sandbox escape, but it does not report active exploitation, a patch, or technical details.

    05083772
    66 followersView on X
  • xvonfers@xvonfers
    Patch

    (CVE-2026-6307)[497404188][compiler] Type Confusion https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html Reported by Project WhatForLunch (@pjwhatforlunch)

    Post summary

    The message highlights CVE‑2026‑6307, a type‑confusion flaw, and points to a Chrome stable‑channel update that presumably contains the patch, while providing no PoC or exploit details.

    001654.8K
    5.0K followersView on X
  • Open-source Projects@the_osps
    Disclosure

    • GhostLock: a 15-year-old stack-UAF affecting all Linux distributions • Longinus: CVE-2026-6307 piercing Chrome's renderer and V8 sandbox • Netfilter bug CVE-2026-23274 exploited for a $10,500 kernelCTF bounty

    Post summary

    The passage announces three vulnerabilities—GhostLock (a long‑standing stack‑UAF on Linux), Longinus (CVE‑2026‑6307 impacting Chrome's renderer and V8 sandbox), and a Netfilter bug (CVE‑2026‑23274) exploited in a CTF—without providing PoCs, exploit code, patches, or evidence of real‑world attacks.

    1000072
    1.6K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor v147.0.7727.101. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-6307 PT ID: PT-2026

    Post summary

    A proof‑of‑concept/exploit for CVE‑2026‑6307 has been discovered, but no details on active exploitation, patching, or technical specifics are provided.

    1000050
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-6307. 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-6307 PT ID: PT-2026

    Post summary

    A PoC/exploit for CVE‑2026‑6307 has been discovered, indicating the vulnerability is exploitable, but no exploitation evidence or patch details are provided.

    1000052
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-6307. Source: X search for CVE-2026 critical Posted: 2026-07-01T00:50:52.000Z Likes: 22

    Post summary

    The post merely lists CVE‑2026‑6307 without providing any technical details, exploit information, or updates.

    1000054
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    Vendor v9.8. Source: X search for CVE-2026 critical Posted: 2026-07-01T00:50:52.000Z Likes: 22 #CVE-2026-6307 V8 Exploit Kit #Longinus 2 Boundaries in One Bug - Piercing Chrome's Renderer and #V8 #Sandbox Overview | Attribute | Value | |-----------|-------| | CVE |…

    Post summary

    The post signals the availability of an exploit kit (Longinus) targeting CVE‑2026‑6307, but offers no evidence of active attacks, patch info, or PoC details.

    1000089
    326 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more